SAML2 Library Vulnerability in SimpleSAMLphp Affects XML Signature Processing
CVE-2026-49289

7.5HIGH

Key Information:

Status
Vendor
CVE Published:
19 August 2026

What is CVE-2026-49289?

The SimpleSAMLphp SAML2 library, utilized for handling SAML2 features, has a security weakness in versions 4.19.2 and 4.20.2 that allows an attacker to control XPath transforms while processing specially crafted XML signatures in SAML messages. This flaw enables a remote unauthenticated attacker to consume excessive processing resources, potentially leading to a denial of service for any system that depends on the SimpleSAMLphp or the SAML2 library. The issue has been addressed in versions 4.19.3 and 4.20.3, where mitigations limit the number of transforms allowed by restricting algorithms to those specified by the SAML 2.0 Core specification and explicitly disallowing XPath transforms.

Affected Version(s)

saml2 >= 4.19.2, < 4.19.3 < 4.19.2, 4.19.3

saml2 >= 4.20.2, < 4.20.3 < 4.20.2, 4.20.3

References

CVSS V3.1

Score:
7.5
Severity:
HIGH
Confidentiality:
None
Integrity:
None
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.